Privacy Policy
Who We Are
Koffyr is a Certificate of Insurance (COI) issuance platform operated by Valtio Inc., a Delaware corporation.
- Legal entity: Valtio Inc.
- Product: Koffyr (koffyr.com)
- Privacy contact: privacy@koffyr.com
This Privacy Policy applies to the Koffyr platform, APIs, and associated services. It does not apply to the websites or services of our customers (insurance agencies and their insureds), who control their own data practices.
Scope
Who this Policy Covers. This Policy covers:
- Agency users — insurance professionals who create and manage accounts on Koffyr.
- Insured users — entities whose certificate data is managed by agencies on the platform, including their principals, employees, and authorized representatives.
- Recipients — certificate holders and additional insureds who receive or review certificates via Koffyr.
- Visitors to koffyr.com and the Koffyr marketing site.
Valtio Inc. as Processor vs. Controller. Valtio Inc. acts in two distinct capacities:
| Capacity | Data | Basis |
|---|---|---|
| Data Controller | Account registration data; billing and subscription data; platform usage analytics | Valtio collects and uses this data for its own purposes |
| Data Processor | Insurance and COI data (policyholder details, certificate fields, insured organizations) entered by agency customers | Valtio processes this on behalf of the agency (the Controller); our Data Processing Agreement governs |
For data where Valtio acts as processor, the agency customer's privacy policy and instructions govern. This Privacy Policy primarily describes Valtio's controller-capacity practices.
Data We Collect
3.1 Account and Identity Data.
| Category | Fields | Collection Method |
|---|---|---|
| Identity | First name, last name | Registration / profile |
| Contact | Email address (KMS-encrypted at rest), phone number (KMS-encrypted at rest) | Registration / profile |
| Profile | Date of birth (KMS-encrypted), home address (KMS-encrypted), avatar photo | Profile setup |
| Authentication | WebAuthn credential IDs, magic-link tokens (one-way hashed) | Auth flow |
| Preferences | Notification preferences, MFA flag | Settings |
Email address, phone number, date of birth, and home address are stored KMS-envelope-encrypted at rest in our database. Blind-index hashes enable equality lookups without exposing plaintext. Decryption occurs only during authorized service operations.
3.2 Organization Data.
| Category | Fields | Collection Method |
|---|---|---|
| Identity | Organization name, type (agency/insured/producer/vendor), handle | Registration |
| Contact | Email (KMS-encrypted), phone (KMS-encrypted), address, website | Profile |
| Business | Tax Identification Number / EIN (AES-GCM-256 + KMS-envelope encrypted; only last-4 mask stored in plaintext), founding date, staff size, jurisdiction | Profile |
| Billing | Stripe customer ID, subscription status, pricing tier, billing dates | Billing |
3.3 Insurance and COI Data (Processor Capacity). When agencies use Koffyr to manage their book of business, we process on their behalf: insured organization records, insurance policy details (carrier, policy number, line of business, limits, named/additional insureds), COI fields, documents uploaded by agencies and insureds, e-signature data (signer identities, timestamps, IP addresses, RFC 3161 timestamps via Entrust TSA), and form submission data.
3.4 Communications Data. Transactional email metadata: SendGrid delivery events (delivery status, bounces, opens, clicks), email addresses used for sending, organization ID threaded through webhooks.
3.5 Usage and Analytics Data. Platform usage events sent to Mixpanel (distinct ID is an opaque UUID; PII is not sent to Mixpanel). Error and performance telemetry: Sentry (exceptions, traces, stack traces; request IDs, user agent, IP). Server-side logs: request IDs, timestamps, HTTP method/path, status codes. Log aggregation via Better Stack (request metadata, IDs, uptime metrics).
3.6 Technical and Device Data. IP addresses (logged in audit events; used for rate limiting and fraud detection), user agent strings, and HTTP request IDs.
3.7 Data We Do NOT Collect. Social Security Numbers (SSNs) of individuals; payment card numbers (Stripe handles all card data; Valtio never sees raw card data); precise geolocation beyond address fields provided by users.
Why We Collect This Data (Legal Bases)
4.1 Controller-Capacity Purposes.
| Purpose | Data Categories | Legal Basis (GDPR) | CCPA Category |
|---|---|---|---|
| Provide the Koffyr platform | Account, org, billing data | Contract performance (Art. 6(1)(b)) | Identifiers; Commercial information |
| Authentication and account security | Email, phone, auth tokens, WebAuthn | Contract; Legitimate interests | Identifiers |
| Billing and subscription management | Stripe ID, subscription data | Contract; Legal obligation | Commercial information |
| Platform communications (transactional) | Contract | Identifiers | |
| Product analytics (aggregated) | Anonymous usage events (Mixpanel) | Legitimate interests | Inferences |
| Error monitoring and reliability | Error traces (Sentry), logs (Better Stack) | Legitimate interests | Internet/network activity |
| Legal compliance and fraud prevention | Audit events, IP, user agent | Legal obligation; Legitimate interests | Identifiers; Internet/network |
| Audit-trail retention (7-year) | Audit events, COI records | Legal obligation (insurance regulations; ESIGN Act; UETA) | Various |
4.2 Processor-Capacity Purposes. When processing insurance and COI data on behalf of agency customers, the legal basis is the agency's instructions under our Data Processing Agreement. Agencies should ensure they have an appropriate basis for sharing this data with Koffyr.
Information We Share
We do not sell personal information. We do not share personal information for third-party advertising.
5.1 Subprocessors. We engage the following service providers to operate the platform. See our Sub-processors page for the full authoritative register.
| Provider | Service | Data Shared | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Compute, database (RDS/PostgreSQL), storage (S3), KMS encryption, AppSync, ElastiCache | All data hosted in our infrastructure | United States (us-east-2) |
| Cloudflare | CDN, WAF, DDoS protection, frontend hosting, Custom Hostnames | IP addresses, HTTP traffic metadata. Origin data for US customers stays in AWS us-east-2; Cloudflare processes only edge request metadata and does not store Personal Data. | Global CDN; HQ United States |
| Twilio SendGrid | Transactional email delivery | Recipient email addresses, email content, delivery event metadata | United States |
| Mixpanel | Product analytics | Anonymous user IDs (UUID), event names, event metadata (no PII) | United States |
| Sentry | Error monitoring and performance | Exception traces, request IDs, user agent, IP | United States |
| Stripe | Payment processing and billing | Organization billing email, Stripe customer ID; card data is Stripe-side only | United States |
| Entrust TSA | RFC 3161 timestamp authority for e-signatures | Document hashes (not document content or personal data) | United States |
| Better Stack, Inc. | Log aggregation and uptime monitoring | Server logs (request metadata, IDs), uptime metrics | United States |
5.2 Other Disclosures. We may disclose personal information: to comply with applicable law, regulation, legal process, or governmental request; to enforce our Terms of Service or protect the rights, property, or safety of Valtio, our customers, or others; or in connection with a merger, acquisition, or sale of all or substantially all of our assets (we will provide notice before transfer and the acquiring entity will be bound by this Policy or provide a materially equivalent policy).
Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and user profile data | Duration of account + 90 days post-closure | Contract; legitimate interests |
| Insurance policy and COI records | Minimum 7 years from the date of issuance | Insurance regulatory requirements; ESIGN Act; UETA |
| Audit events | Minimum 7 years | Insurance regulations; legal obligation; SOC 2 control evidence |
| E-signature records (Certificate of Completion, TSA timestamps) | Minimum 7 years | ESIGN Act; UETA; insurance regulatory requirements |
| Billing and transaction records | 7 years | Tax/financial record-keeping obligations |
| Transactional email logs | 12 months | Legitimate interests (delivery troubleshooting) |
| Error/telemetry (Sentry) | 90 days | Legitimate interests |
Erasure vs. retention: For insurance records, deletion may not be possible if it would conflict with regulatory minimum-retention obligations. In such cases, we will anonymize data to the extent permitted while retaining the minimum required record. Deletion requests for insurance-regulated data (7-year minimum) will be honored at the end of the regulatory retention period.
Security
We use appropriate technical and organizational measures to protect personal information, including:
- Encryption at rest: Sensitive PII fields (email, phone, date of birth, home address, TIN) are KMS-envelope-encrypted (AES-GCM-256) in our PostgreSQL database.
- Encryption in transit: TLS 1.2 minimum with TLS 1.3 negotiated for all data in transit; Cloudflare terminates public HTTPS traffic.
- Authentication: WebAuthn (passkeys), magic-link OTP, and session tokens with short TTL.
- Access control: Role-based access control (RBAC); least-privilege principle applied to AWS IAM roles.
- Audit logging: Immutable audit trail for all resource changes; tamper-evident daily digest.
- Backups: Continuous database backups with point-in-time recovery (PITR), plus immutable weekly recovery points retained 35 days; a documented restore runbook is in place and the first full restore drill is scheduled for Q4 2026.
No system is 100% secure. If you believe your information has been compromised, please contact us at security@koffyr.com.
Data Subject Rights
8.1 GDPR Rights (EEA/UK Residents). If you are in the European Economic Area or United Kingdom, you have the right to:
- Access (Art. 15): Request a copy of personal data we hold about you.
- Rectification (Art. 16): Correct inaccurate personal data.
- Erasure (Art. 17): Request deletion of personal data, subject to our legal retention obligations. For insurance and COI records, regulatory minimum-retention requirements may prevent full erasure; we will anonymize to the extent permissible.
- Restriction of processing (Art. 18): Restrict how we process your data in certain circumstances.
- Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Objection (Art. 21): Object to processing based on legitimate interests.
- Withdraw consent (Art. 7(3)): Where processing is based on consent, withdraw at any time.
- Lodge a complaint (Art. 77): File a complaint with your local data protection authority.
To exercise your rights, contact privacy@koffyr.com. We will respond within 30 days (extendable to 60 days for complex requests, with notice).
8.2 CCPA Rights (California Residents). If you are a California resident, under the California Consumer Privacy Act (as amended by CPRA), you have the right to:
- Know what personal information we collect, use, and disclose (categories and specific pieces).
- Delete personal information, subject to legal exceptions including insurance regulatory retention requirements.
- Correct inaccurate personal information.
- Opt-out of sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising.
- Limit use of sensitive personal information — we use sensitive PI (TIN, financial information) only to provide the requested services; no secondary uses.
- Non-discrimination — we will not discriminate against you for exercising your rights.
To submit a CCPA request, contact privacy@koffyr.com. We will verify your identity before processing deletion or access requests. You may designate an authorized agent to submit requests on your behalf; we require written proof of authorization.
International Transfers
Our primary data storage and processing is in the United States (AWS us-east-2).
If you are located outside the United States, your personal information will be transferred to and processed in the United States. Koffyr currently serves customers in the United States. GDPR and UK GDPR sections are included for completeness and future EU/UK expansion; no EU/EEA data subjects are actively served at this time.
For data processed under our DPA (processor capacity), the transfer mechanisms — including Module 2 Standard Contractual Clauses for EEA transfers — are specified in the DPA.
Children's Privacy
Koffyr is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware of such collection, we will delete it promptly.
Cookies and Tracking
koffyr.com (marketing site). This site sets no cookies and runs no analytics or tracking scripts. No consent banner is required for this site.
app.koffyr.com (Koffyr app). The app sets one essential cookie:
- valtio-auth-session — iron-session sealed, essential/authentication. This cookie is necessary to maintain your logged-in session. It is not used for advertising or cross-site tracking.
Product analytics. The Koffyr app sends usage events to Mixpanel using an anonymous opaque identifier (UUID). No personally identifiable information (name, email, phone) is sent to Mixpanel. No advertising cookies or cross-site tracking cookies are used.
We do not use advertising networks, retargeting, or cross-site behavioral tracking cookies on any Koffyr property.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email (to the address on your account) or by prominent notice on the platform at least 30 days before the effective date. Your continued use of Koffyr after the effective date constitutes acceptance of the updated Policy.
Contact Us
For privacy-related inquiries, requests, or complaints:
Valtio Inc.
Email: privacy@koffyr.com
Registered mailing address available on request.